tobi60
1
Hi everybody,
i am currently trying to build an alert, which will be triggered if a message has just existed and already existed 10 minutes ago.
Example:
message: “Test” -> true & message: “Test” (10 minutes ago) -> true ==> Trigger alert
Does anyone of you know a solution to this problem?
Thanks
jan
(Jan Doberstein)
2
he @tobi60
that is what the correlation feature is given for.
tobi60
3
Thanks for the quick answer.
I am currently using Graylog Open Source, so there is no way to use any workaround for this feature?
tmacgbay
(Tmacgbay)
4
If you are ingesting less than 5G a day, you can apply for a free enterprise license.
system
(system)
Closed
5
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.